Privacy Policy

Personal data · experimental processing

Privacy Policy

Last updated 16 September 2026 · Effective immediately · Experimental system

This Privacy Policy explains what information Primacy Vault processes, why, how long, with whom it is shared, and the choices you have. It is written for a global audience and is intended to satisfy transparency duties under the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and similar laws, without claiming that Primacy is established in every jurisdiction or that a Data Protection Officer has been appointed. If a conflict exists between this Policy and a non-waivable statute that applies to you, that statute controls.

1. Controller, processors, and experimental status

Until a formed entity is named in a later notice, the operator of the Platform is the controller of personal data processed to run your account. xAI is a processor / sub-processor when you invoke SuperGrok. Hosting, analytics (if enabled), and any future SMTP/Resend provider are processors for their respective functions. Circle, public blockchains, and your own email provider are independent controllers of data you send to them.

This environment may store account, palace, wallet-link, outreach, and mail-outbox data locally to the session (for example in browser storage) until a production backend you approve is connected. Local storage is still personal data if it identifies you.

2. Categories of personal data

Account data: email, password verifier or equivalent, display name, selected plan, industry, timestamps.

Vault and palace data: rooms, entries, triples, tunnels, AAAK summaries, SuperGrok briefs and outputs you generate. This may include sensitive professional opinions. Do not put health, children’s, or government-ID data in the palace unless you have a lawful basis and accept the experimental risk.

Wallet data: public addresses you link, active-address selection, stake and royalty ledger entries. We do not ask for seed phrases. Never paste a seed phrase into SuperGrok or a support form.

Outreach data: campaign metadata, buyer company names you type, buyer emails you type, letter subject/body, Auditor verdicts, job amounts, send/reply timestamps you log.

Mail data: transactional messages queued or sent to YOUR email (letter ready, job activation, receipts), delivery status if a provider returns it.

Technical data: device/browser type, approximate timestamps, error logs, and security events. We do not need your precise GPS location.

We do not intentionally collect data from children under 16 (13 in the U.S. where COPPA applies). If we learn we have, we will delete it.

3. Purposes and legal bases (GDPR-style)

Perform the contract / requested service: account, vault, outreach OS, royalty ledger, transactional mail to you (Art. 6(1)(b) GDPR where it applies).

Legitimate interests: security, abuse detection, anti-hallucination scanning, product improvement of prompts, defending legal claims (Art. 6(1)(f)), balanced against your rights. You may object where that law applies.

Consent: optional cookies beyond strictly necessary; marketing mail if we ever send it (we do not as of this date). Withdrawal does not affect prior processing.

Legal obligation: tax, sanctions screening, or lawful process if and when a production operator is subject to those duties.

4. Sharing

xAI: prompts and necessary context when you click a SuperGrok action. Do not include secrets you do not want a model provider to process.

Mail transport: Resend or SMTP, only if connected, and only for messages addressed to you unless you explicitly trigger a company send after that transport is documented as live.

Public blockchains: if you later sign transactions, those payloads are public and permanent. Preview records are not chain publications.

Service hosts, auditors, and professional advisers under confidentiality.

A buyer of your module receives only what you approve for listing or attach to a job. We do not sell personal information as defined by the CCPA. We do not share for cross-context behavioral advertising as of this date.

We may disclose if required by law, to prevent harm, or in a merger/asset transfer of the experiment, with notice where legally required.

5. Retention

Account and vault: for the life of the account plus a short wind-down, unless you delete.

Outreach and mail outbox: for the life of the account so you can prove what you logged; you may delete campaigns in-product where that control exists.

SuperGrok logs: short operational retention in-product; xAI retains according to its own policy.

Legal hold: we may retain a copy if we reasonably anticipate a dispute.

When the production backend arrives, retention schedules will be republished. Until then, clearing browser storage may destroy your only copy. Export anything you cannot afford to lose.

6. International transfers

xAI and many hosts process in the United States. If you are in the EEA/UK/Switzerland, this is a third-country transfer. Standard Contractual Clauses or successor mechanisms will be put in place with processors when the production backend is contracted. Until then, experimental use is at your risk. You may choose not to invoke SuperGrok.

7. Your rights

Depending on law, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. CCPA/CPRA: rights to know, delete, correct, and opt out of sale/share (we do not sell/share as of this date), and not to be discriminated against for exercising rights. We will not honor a request we cannot authenticate.

Submit requests via the contact method in the FAQ. We will respond within the statutory period (typically 30–45 days) once a production identity-verification path exists. In this experimental environment, deleting your account data in-product / clearing storage is the practical deletion path.

EEA/UK users may complain to a supervisory authority. U.S. users may contact a state attorney general. This does not waive our position that the Platform is experimental.

8. Security

We apply best-effort technical and organizational measures appropriate to an experimental app: transport encryption in production hosting, access minimization, anti-hallucination scanning, and wallet-connect gating for money actions. No method is 100% secure. You must use a unique password, protect keys, and treat SuperGrok output as untrusted.

SOC 2: we are not certified. See the Trust page for the control mapping we operate toward.

9. Cookies

See the Cookie Policy. Strictly necessary cookies/storage keep you logged in and remember linked wallets. We do not currently run advertising pixels.

10. Changes

We will post updates with a new date. Material changes that expand processing in a way that requires consent will be put behind a consent step where law requires it.

This Policy is interpreted under the laws of the State of Wyoming, United States, consistent with the Terms of Service. Exclusive venue is Laramie County, Wyoming, except where a non-waivable statute requires otherwise.

These documents are not a substitute for independent legal, tax, or investment advice. Primacy Vault is experimental. User beware.